docs: SELC-9170 multitenant JWT signing requirements, architecture and security - #767
Open
andrea-putzu wants to merge 2 commits into
Open
docs: SELC-9170 multitenant JWT signing requirements, architecture and security#767andrea-putzu wants to merge 2 commits into
andrea-putzu wants to merge 2 commits into
Conversation
andrea-putzu
requested review from
a team,
fabiosalamonenttdata,
giampiero-ferrara and
giulia-tremolada
as code owners
August 25, 2026 07:03
|
Warning
|
| Severity | ID | File | Line | Title |
|---|---|---|---|---|
| HIGH | AVD-DX-0001 | infra/bootstrap/_modules/github_repository_environment/main.tf |
L53 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/_modules/github_repository_environment/main.tf |
L53 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/_modules/github_repository_environment/main.tf |
L53 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/_modules/github_repository_environment/main.tf |
L53 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/_modules/github_repository_environment/main.tf |
L53 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/_modules/github_repository_environment/main.tf |
L53 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/_modules/github_repository_environment/main.tf |
L53 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/_modules/github_repository_environment/main.tf |
L53 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/_modules/github_repository_environment/main.tf |
L53 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/dev-ar/data.tf |
L25 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/dev-ar/data.tf |
L20 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/dev-ar/data.tf |
L35 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/dev-ar/data.tf |
L30 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/dev-ar/data.tf |
L11 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/prod-ar/data.tf |
L25 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/prod-ar/data.tf |
L20 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/prod-ar/data.tf |
L35 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/prod-ar/data.tf |
L30 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/prod-ar/data.tf |
L11 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/uat-ar/data.tf |
L25 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/uat-ar/data.tf |
L20 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/uat-ar/data.tf |
L35 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/uat-ar/data.tf |
L30 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/bootstrap/uat-ar/data.tf |
L11 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/cert/_modules/cert/data.tf |
L7 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/cert/_modules/cert/data.tf |
L7 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/cert/_modules/cert/data.tf |
L7 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/cert/_modules/cert/data.tf |
L7 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/cert/_modules/cert/data.tf |
L7 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/cert/_modules/cert/data.tf |
L7 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L35 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L35 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L35 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L45 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L45 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L45 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L55 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L55 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L55 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L40 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L40 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L40 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L71 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L71 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L71 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L50 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L50 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L50 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L60 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L60 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L60 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L76 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L76 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/apim/data.tf |
L76 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/data/azure_key_vault_items/main.tf |
L11 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/data/azure_key_vault_items/main.tf |
L11 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/data/azure_key_vault_items/main.tf |
L11 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/data/azure_key_vault_items/main.tf |
L22 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/data/azure_key_vault_items/main.tf |
L16 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/data/azure_key_vault_items/main.tf |
L28 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/data/azure_key_vault_items/main.tf |
L28 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/data/azure_key_vault_items/main.tf |
L28 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/data/docker_credentials/main.tf |
L6 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/data/docker_credentials/main.tf |
L1 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L26 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L26 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L26 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L26 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L26 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L26 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L31 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L31 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L31 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L31 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L31 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L31 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L36 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L36 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L36 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L36 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L36 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L36 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L41 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L41 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L41 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L41 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L41 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L41 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L159 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L159 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L159 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L159 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L159 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L159 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L92 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L92 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L92 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L92 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L92 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L92 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L117 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L117 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L117 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L117 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L117 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L117 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L164 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L164 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L164 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L164 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L164 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/key_vault/main.tf |
L164 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L76 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L76 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L76 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L81 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L81 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L81 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L96 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L96 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L96 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L86 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L86 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L86 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L91 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L91 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/monitor/main.tf |
L91 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/spid_testenv/spid-testenv.tf |
L14 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/spid_testenv/spid-testenv.tf |
L14 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/spid_testenv/spid-testenv.tf |
L9 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/_modules/spid_testenv/spid-testenv.tf |
L9 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/dev-pnpg/app.tf |
L33 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/prod-pnpg/app.tf |
L24 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/uat-ar/commons.tf |
L541 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/core/uat-pnpg/app.tf |
L33 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/apim.tf |
L1679 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/apim.tf |
L1679 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/apim.tf |
L1679 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/apim.tf |
L1684 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/apim.tf |
L1684 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/apim.tf |
L1684 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/apim.tf |
L1689 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/apim.tf |
L1689 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/apim.tf |
L1689 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L35 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L35 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L35 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L45 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L45 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L45 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L55 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L55 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L55 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L40 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L40 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L40 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L71 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L71 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L71 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L50 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L50 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L50 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L60 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L60 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L60 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L76 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L76 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/apim_external_api/data.tf |
L76 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/dapr/data.tf |
L17 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/dapr/data.tf |
L17 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/dapr/data.tf |
L17 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/functions/function.tf |
L87 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/functions/function.tf |
L87 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/functions/function.tf |
L87 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/functions/function.tf |
L87 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/functions/function.tf |
L87 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/functions/function.tf |
L87 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/namirial_sws/data.tf |
L15 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/namirial_sws/data.tf |
L15 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/namirial_sws/data.tf |
L15 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/namirial_sws/data.tf |
L10 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/namirial_sws/data.tf |
L10 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | infra/resources/_modules/namirial_sws/data.tf |
L10 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | libs/selfcare-commons/infra/terraform-modules/github_repository_settings/data.tf |
L22 | Terraform must not read Key Vault secrets via data source |
| HIGH | AVD-DX-0001 | libs/selfcare-commons/infra/terraform-modules/github_repository_settings/data.tf |
L17 | Terraform must not read Key Vault secrets via data source |
📋 Pre-commit Output LogGenerated on Tue Aug 25 09:59:16 UTC 2026 |
📖 Terraform Plan (infra/resources/auth/dev-ar) - successShow Plan # module.container_app_auth_ms.azurerm_container_app.container_app will be updated in-place
~ resource "azurerm_container_app" "container_app" {
id = "/subscriptions/1ab5e788-3b98-4c63-bd05-de0c7388c853/resourceGroups/selc-d-container-app-002-rg/providers/Microsoft.App/containerApps/selc-d-auth-ms-ca"
name = "selc-d-auth-ms-ca"
tags = {
"CostCenter" = "TS310 - PAGAMENTI & SERVIZI"
"CreatedBy" = "Terraform"
"Environment" = "Dev"
"Owner" = "Selfcare"
"Source" = "https://github.com/pagopa/selfcare"
}
# (10 unchanged attributes hidden)
- secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
- secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
- secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
- secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
- secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
- secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
- secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
- secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
- secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
- secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
- secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
- secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
- secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
+ secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
+ secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
+ secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
+ secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
+ secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
+ secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
+ secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
+ secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
+ secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
+ secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
+ secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
+ secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
+ secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
+ secret {
# At least one attribute in this block is (or was) sensitive,
# so its contents will not be displayed.
}
~ template {
# (6 unchanged attributes hidden)
~ container {
~ image = "ghcr.io/pagopa/selfcare-auth-ms:sha-e9077c7" -> "ghcr.io/pagopa/selfcare-auth-ms:sha-$(git r"
name = "selc-d-auth-ms"
# (5 unchanged attributes hidden)
~ env {
~ name = "SESSION_TOKEN_PRIVATE_KEY" -> "TENANT_AR_JWT_SESSION_KEY_ID"
~ secret_name = "jwt-private-key-pkcs8" -> "jwt-kid"
# (1 unchanged attribute hidden)
}
~ env {
~ name = "TENANT_AR_ONE_IDENTITY_CLIENT_ID" -> "TENANT_AR_JWT_SESSION_PRIVATE_KEY"
~ secret_name = "oneidentity-client-id" -> "jwt-private-key-pkcs8"
# (1 unchanged attribute hidden)
}
~ env {
~ name = "TENANT_AR_ONE_IDENTITY_CLIENT_SECRET" -> "TENANT_AR_ONE_IDENTITY_CLIENT_ID"
~ secret_name = "oneidentity-client-secret" -> "oneidentity-client-id"
# (1 unchanged attribute hidden)
}
~ env {
~ name = "USER_REGISTRY_API_KEY" -> "TENANT_AR_ONE_IDENTITY_CLIENT_SECRET"
~ secret_name = "user-registry-api-key" -> "oneidentity-client-secret"
# (1 unchanged attribute hidden)
}
+ env {
+ name = "USER_REGISTRY_API_KEY"
+ secret_name = "user-registry-api-key"
}
# (32 unchanged blocks hidden)
}
# (1 unchanged block hidden)
}
# (2 unchanged blocks hidden)
}
# module.apim_api_auth.module.apim_api.azurerm_api_management_api.this will be updated in-place
~ resource "azurerm_api_management_api" "this" {
+ description = "Auth API"
id = "/subscriptions/1ab5e788-3b98-4c63-bd05-de0c7388c853/resourceGroups/selc-d-api-v2-rg/providers/Microsoft.ApiManagement/service/selc-d-apim-v2/apis/selc-d-api-auth;rev=1"
name = "selc-d-api-auth"
# (16 unchanged attributes hidden)
# (2 unchanged blocks hidden)
}
# module.apim_api_auth.module.apim_api.azurerm_api_management_api_policy.this[0] will be updated in-place
~ resource "azurerm_api_management_api_policy" "this" {
id = "/subscriptions/1ab5e788-3b98-4c63-bd05-de0c7388c853/resourceGroups/selc-d-api-v2-rg/providers/Microsoft.ApiManagement/service/selc-d-apim-v2/apis/selc-d-api-auth"
~ xml_content = <<-EOT
- <policies>
+ <policies>
- <inbound>
+ <inbound>
- <cors allow-credentials="true">
+ <cors allow-credentials="true">
- <allowed-origins>
+ <allowed-origins>
- <origin>http://localhost:3000</origin>
+ <origin>http://localhost:3000</origin>
- <origin>https://dev.selfcare.pagopa.it</origin>
+ <origin>https://dev.selfcare.pagopa.it</origin>
- <origin>https://api.dev.selfcare.pagopa.it</origin>
+ <origin>https://api.dev.selfcare.pagopa.it</origin>
- <origin>https://pnpg.dev.selfcare.pagopa.it</origin>
+ <origin>https://pnpg.dev.selfcare.pagopa.it</origin>
- <origin>https://api-pnpg.dev.selfcare.pagopa.it</origin>
+ <origin>https://api-pnpg.dev.selfcare.pagopa.it</origin>
- </allowed-origins>
+ </allowed-origins>
- <allowed-methods>
+ <allowed-methods>
- <method>GET</method>
+ <method>GET</method>
- <method>POST</method>
+ <method>POST</method>
- <method>PUT</method>
+ <method>PUT</method>
- <method>HEAD</method>
+ <method>HEAD</method>
- <method>DELETE</method>
+ <method>DELETE</method>
- <method>OPTIONS</method>
+ <method>OPTIONS</method>
- </allowed-methods>
+ </allowed-methods>
- <allowed-headers>
+ <allowed-headers>
- <header>Authorization</header>
+ <header>Authorization</header>
- <header>Content-Type</header>
+ <header>Content-Type</header>
- <header>Accept</header>
+ <header>Accept</header>
- <header>traceparent</header>
+ <header>traceparent</header>
- <header>tracestate</header>
+ <header>tracestate</header>
- </allowed-headers>
+ </allowed-headers>
- </cors>
+ </cors>
- <set-variable name="tenantId" value="@{
+ <set-variable name="tenantId" value='@{
var host = context.Request.OriginalUrl.Host;
if (string.IsNullOrWhiteSpace(host)) {
return string.Empty;
}
host = host.ToLowerInvariant();
if (host == "api.dev.selfcare.pagopa.it") {
return "AR";
}
if (host == "api-pnpg.dev.selfcare.pagopa.it") {
return "PNPG";
}
return string.Empty;
- }" />
+ }' />
- <choose>
+ <choose>
- <when condition="@((string)context.Variables["tenantId"] == string.Empty)">
+ <when condition='@((string)context.Variables["tenantId"] == string.Empty)'>
- <trace source="tenant-audit" severity="error">
+ <trace source="tenant-audit" severity="error">
- <message>@("event=tenant_request_rejected reason=unknown_host operation=" + (context.Operation == null ? "unknown" : context.Operation.Id))</message>
+ <message>@("event=tenant_request_rejected reason=unknown_host operation=" + (context.Operation == null ? "unknown" : context.Operation.Id))</message>
- </trace>
+ </trace>
- <return-response>
+ <return-response>
- <set-status code="403" reason="Forbidden" />
+ <set-status code="403" reason="Forbidden" />
- <set-header name="Content-Type" exists-action="override">
+ <set-header name="Content-Type" exists-action="override">
- <value>application/problem+json</value>
+ <value>application/problem+json</value>
- </set-header>
+ </set-header>
- <set-body>{"title":"Forbidden","status":403,"detail":"Invalid tenant context"}</set-body>
+ <set-body>{"title":"Forbidden","status":403,"detail":"Invalid tenant context"}</set-body>
- </return-response>
+ </return-response>
- </when>
+ </when>
- </choose>
+ </choose>
- <set-header name="X-Tenant-Id" exists-action="override">
+ <set-header name="X-Tenant-Id" exists-action="override">
- <value>@((string)context.Variables["tenantId"])</value>
+ <value>@((string)context.Variables["tenantId"])</value>
- </set-header>
+ </set-header>
- <base />
+ <base />
- </inbound>
+ </inbound>
- <backend>
+ <backend>
- <base />
+ <base />
- </backend>
+ </backend>
- <outbound>
+ <outbound>
- <base />
+ <base />
- </outbound>
+ </outbound>
- <on-error>
+ <on-error>
- <base />
+ <base />
- </on-error>
+ </on-error>
</policies>
EOT
# (4 unchanged attributes hidden)
}
Plan: 0 to add, 3 to change, 0 to destroy. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
List of Changes
Adds documentation for SELC-9170: Multitenant JWT signing for the
authmicroservice, underapps/docs/Multitenant/Step_0/SELC-9170/:REQUIREMENTS.md: functional requirements for tenant-specific JWT signing/verification (Section 2, SELC-2.x) and verification-key selection / token exchange (Section 3, SELC-3.x), covering:infra/certTerraform automation, with private key material stored only in Azure Key Vault.authvalidates all enabled tenant signing keys at startup; a missing/invalid key prevents the container from becoming ready (no request-level error).dev-pnpgcertificate resources intodev-ar, using new tenant-suffixed resources (_ar/_pnpg) rather than in-place Terraform state migration, avoiding dual-ownership risk.X-Tenant-Id, then select the JWT signing key using the token'skidfrom that tenant's JWKS;tenant_idinside the JWT is only trusted after signature verification succeeds.dashboard-bff's token-exchange flow embedstenant_idin every exchange token, sourced from the already-validated request tenant context.ARCHITECTURE.md: provisional architecture (7 design points) covering tenant-specific signing config, startup-time fail-closed validation, JWT verification boundary, tenant propagation, key lifecycle, dev certificate consolidation, and the dashboard token-exchange boundary, plus a requirement traceability table and dependency rules.SECURITY.md: security rules derived from the architecture, organized by HTTP/APIM trust boundary, tenant-specific JWT issuance, JWT verification (with temporary PNPG fallback), dashboard JWT exchange, tenant authorization/propagation, secret and key management, input validation/logging, and deployment/CI safety, with selected manicode prompt references.This is a documentation-only change; no application or Terraform code was modified.
Motivation and Context
The
authmicroservice currently supports a single tenant per deployment. To support multiple tenants (e.g.selfcare.pagopa.itandimprese.notifichedigitali.it) from a single backend deployment,authneeds tenant-aware JWT signing/verification, tenant propagation viaX-Tenant-Id, and a clear key lifecycle strategy. This PR documents the agreed requirements, architecture, and security rules for that work before implementation begins.How Has This Been Tested?
N/A — documentation-only change. Content was cross-checked against the existing
infra/certTerraform modules (JWKS/CDN publication) anddashboard-bfftoken-exchange code to ensure accuracy.Screenshots (if appropriate):
N/A
Types of changes
Checklist: